Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    default deny rule blocking allowed traffic

    Firewalling
    2
    12
    482
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      Popolou
      last edited by Popolou

      If you reset the states does that still occur? The second server is configured for TCP rather than UDP?

      Z 1 Reply Last reply Reply Quote 0
      • Z
        ziggy94 @Popolou
        last edited by

        @Popolou 1195 is for a p2p that is unrelated.
        The active primary remote access is 1194.
        I did reset the state and I got the same error.

        P 1 Reply Last reply Reply Quote 0
        • P
          Popolou @ziggy94
          last edited by

          @ziggy94 Sure, but i am referring to the second OpenVPN server as you wrote, not the second table entry.

          Z 1 Reply Last reply Reply Quote 0
          • Z
            ziggy94 @Popolou
            last edited by

            @Popolou yes the second one is to be used by end users while primary is for IT.
            Should the second one be set for UDP over TCP even if it's not for a fail over or something along those lines?

            Z P 2 Replies Last reply Reply Quote 0
            • Z
              ziggy94 @ziggy94
              last edited by

              @ziggy94 UDP instead of TCP* sorry that was poor wording.

              1 Reply Last reply Reply Quote 0
              • P
                Popolou @ziggy94
                last edited by Popolou

                @ziggy94 Either is fine & UDP is default but TCP is 443 IIRC. Is the second server configured to use the WAN interface?

                Z 1 Reply Last reply Reply Quote 0
                • Z
                  ziggy94 @Popolou
                  last edited by

                  @Popolou sorry, I'm not sure what you mean here.

                  1 Reply Last reply Reply Quote 0
                  • P
                    Popolou
                    last edited by

                    Check your settings for the second OpenVPN server, such that this is what it should be for the default: -

                    fe0999fb-c766-4fac-8ef1-0c4c4c7ab2de-image.png

                    If you want the second server to work against that FW rule, you want to change the protocol to TCP and the port to 1196 on the WAN.

                    Z 2 Replies Last reply Reply Quote 0
                    • Z
                      ziggy94 @Popolou
                      last edited by

                      @Popolou yes so the default server was that and I did change it to use TCP instead of UDP on port 1194. That is the primary used by IT.
                      The secondary one I just built yesterday using TCP on port 1196.
                      both are using the WAN.
                      so did I make a config error here?

                      P 1 Reply Last reply Reply Quote 0
                      • Z
                        ziggy94 @Popolou
                        last edited by

                        @Popolou It's been a long day so sorry if I am just being a bit dense here. haha

                        1 Reply Last reply Reply Quote 0
                        • P
                          Popolou @ziggy94
                          last edited by

                          @ziggy94 Cannot see one myself. There is no special routing going on presumably? Very odd especially if one server is running well. Perhaps leave everything as is and do a reboot to see if that cleans things up. Not convenient, i know.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.